CVE-2019-0165: Input Validation
Published Dec 18, 2019
·Updated
Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.
Affected Software
3 affected components
Intel Converged Security Management Engine Firmware>=12.0<12.0.45
Intel Converged Security Management Engine Firmware>=13.0<13.0.10
Intel Converged Security Management Engine Firmware>=14.0.0<14.0.10
Event History
Dec 18, 2019
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-0165.
2
What is the title of this vulnerability?
The title of this vulnerability is "Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10, and 14.0.10."
3
What is the severity of CVE-2019-0165?
The severity value of CVE-2019-0165 is 4.4 (Medium).
4
Which software versions are affected by CVE-2019-0165?
The Intel Converged Security Management Engine Firmware versions 12.0 (up to 12.0.45), 13.0 (up to 13.0.10), and 14.0 (up to 14.0.10) are affected.
5
How can a privileged user potentially exploit this vulnerability?
A privileged user may be able to enable denial of service via local access.